You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
" definition: 'Requirements: install and apply the RPC Firew all to all processes with \"audit:true action:block uuid:df1941c5-fe89-4e79-bf10-463657acf44d or c681d488-d850-11d0-8c52-00c04fd90f7e'\n" +
192
+
"detection:\n" +
193
+
" selection:\n" +
194
+
" EventID: 22\n" +
195
+
" RecordNumber: null\n" +
196
+
" condition: selection\n" +
197
+
"falsepositives:\n" +
198
+
" - Legitimate usage of remote file encryption\n" +
199
+
"level: high";
200
+
}
201
+
171
202
publicstaticStringrandomRuleWithKeywords() {
172
203
return"title: Remote Encrypting File System Abuse\n" +
173
204
"id: 5f92fff9-82e2-48eb-8fc1-8b133556a551\n" +
@@ -1353,6 +1384,44 @@ public static String randomDocOnlyNumericAndText(int severity, int version, Stri
0 commit comments